Insufficient path validation when writing a file via WebDAV in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HSouthrivertech Titan Mfp Server
APPSouthrivertech< 2.0.18
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
Related vulnerabilities
CVE-2023-45685CRITICAL9.1PL ✓same vendor
Path traversal przy rozpakowywaniu ZIP w Titan MFT i Titan SFTP Server
CVE-2022-34005CRITICAL9.8PL ✓same vendor
RCE przez zakodowane hasło konta SA w TitanFTP NextGen
CVE-2023-45687HIGH8.8same vendor
A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Wi...
CVE-2023-27744HIGH7.8same vendor
An issue was discovered in South River Technologies TitanFTP NextGen server that allows for a vertical privile...
CVE-2023-27745HIGH8.8same vendor
An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to...